Skip to content

AI Security & Safety Engineer

Ammly Kinyua

I work on the security and safety of AI systems. That means adversarial testing of agents and guardrails, and the engineering that keeps a compromised model from reaching anything that matters.

My independent work is adversarial and public. I reproduce attacks, publish what held and what did not, and teach the same material to students who will run into it for real.

21/44
Prompts the best commercial guardrail blocked
13/13
Adversarial inputs the CONTAGION judge caught
9
Kenyan regions running the security labs

02 / research

Research & Public Work

Adversarial work on agentic systems, guardrails and the platforms they run on. The numbers are from the evaluations, and the failures are written up alongside them.

contagionResearch

CONTAGION

A reproduction of the Morris II zero-click GenAI worm across a mesh of eight tool-using agents, with an LLM judge as the only guardrail. The interesting results are the guardrail's failures, not its catches.

13/13
Detection
12.5%
False positives
8
Agents
FastAPIGoogle ADKGemini 2.5Next.js+2
SourceRead
misalignment-labResearch

Misalignment Lab

An elicitation harness for agentic misbehaviour. Three constructed scenarios in which an autonomous agent under pressure reaches for coercion, social engineering, or exfiltration. An existence proof, deliberately, rather than a base rate.

3
Scenarios
Elicitation
Framing
2026
Extended
FastAPIGoogle ADKNext.jsThree.js+2
SourceRead
guardrail-evaluationResearch

Guardrail Evaluation in Swahili and Sheng

An adversarial test suite of 44 prompts across seven attack categories, with a Kenyan PII corpus and a Swahili/Sheng attack corpus, run against commercial AI guardrail products. Products marketed as multilingual performed poorly outside English.

44
Prompts
7
Categories
21/44
Best product
PromptfooOWASP LLM Top 10MITRE ATLASNIST AI RMF+1
Read
break-and-secureLive

Break & Secure: Cyber x AI

Six hands-on Colab labs where students build a small AI app, break it with real techniques, then secure it and re-run the same attacks to watch the defences hold. Taught across Kenyan universities.

6
Labs
35
Forks
9
Regions
Google ColabPythonOpenAI SDKLiteLLM+2
SourceRead
threat-intelligence-platformLive

Threat Intelligence Platform

An enterprise CTI platform processing over 100,000 daily events from OSINT and dark web sources, with an analysis engine on Vertex AI for automated summarisation, MITRE ATT&CK mapping and TTP classification.

100K+
Daily events
Sub-second
Retrieval
95% faster
Response time
PythonFastAPIPostgreSQLpgvector+3
Read
cyber-defender-snakeLive

CyberDefender Snake

A security workshop built as a playable Snake game. Co-built for Decode 4.0 and still the most-forked thing I have written.

42
Forks
Decode 4.0
Event
None
Install
TypeScriptViteCanvasWeb
SourceRead

03 / experience

Experience

Five years building and defending platforms at telecom scale, then moving the same work onto AI systems.

  1. Jan 2026 to PresentCurrent

    AI Security Engineer, Cyber Security Architecture & Engineering

    Safaricom PLC

    Leading the AI security function across two pillars: securing the AI systems the business builds and procures, and applying AI to cyber defence.

    • Lead the AI security function across two pillars, securing the AI the business builds and buys, and applying AI to cyber defence
    • Set the controls and review process for agent and LLM application architectures before they reach production
    • Built the adversarial guardrail evaluation described under Research, including the Kenyan PII and Swahili/Sheng corpora
    • Own security review against OWASP LLM Top 10 (2025), the OWASP Agentic Top 10, MITRE ATLAS and NIST AI RMF
    • Run the evaluation gate that AI security products pass before organisation-wide adoption
    PromptfooOWASP LLM Top 10MITRE ATLASNIST AI RMFGoogle ADKVertex AIPython
  2. Nov 2024 to Dec 2025

    Security Engineer, Threat Intelligence Platform

    Safaricom PLC

    Architected and built the threat intelligence platform, processing over 100,000 daily events from OSINT and dark web sources with an analysis engine on Vertex AI.

    • Architected and built the platform, processing over 100,000 daily events from OSINT and dark web sources
    • Built the analysis engine on Vertex AI for automated summarisation, MITRE ATT&CK mapping and TTP classification
    • Achieved sub-second vector retrieval across millions of indicators using PostgreSQL with pgvector
    • Integrated automated response with EDR and SIEM, cutting analyst response time by roughly 95 percent
    • Rotated through GRC, Cyber Defence and Cyber Prevent
    PythonFastAPIPostgreSQLpgvectorVertex AIGKEMITRE ATT&CK
  3. Jul 2019 to Oct 2024

    Software Engineer II, Platform & VAS Engineering

    Safaricom PLC

    Led development of the Rich Communication Services platform and the abuse and fraud controls on it, and built fault-tolerant telecom APIs for FTTH, 4G and 5G networks.

    • Led development of the Rich Communication Services platform at national scale
    • Built the abuse and fraud controls on it: rate limiting, circuit breakers, message validation and sender authentication
    • Built fault-tolerant telecom APIs for FTTH, 4G and 5G networks in Python and Django
    • Ran CI/CD on Docker, Kubernetes and Jenkins, including image hardening and secrets handling
    • Cut deployment time by 60 percent
    PythonDjangoDockerKubernetesJenkinsPostgreSQLRedisKafka
  4. Nov 2017 to Jun 2019

    Full Stack Web Developer

    Sawasawa Ltd

    Built Python, Django and JavaScript web applications and REST APIs on a microservices architecture.

    • Built Python, Django and JavaScript web applications and REST APIs
    • Worked on a microservices architecture
    PythonDjangoJavaScriptREST APIsMicroservices
  5. Nov 2017 to Jun 2018

    Full Stack Developer

    Centum Learning Ltd

    Built e-learning and mobile training platforms for corporate onboarding.

    • Built e-learning and mobile training platforms for corporate onboarding
    PHPJavaScriptMySQLMobile Web

04 / teaching

Teaching & Speaking

Reading about an attack and having broken something yourself are not the same thing. The labs are built around the second one.

  • AI security builder labs, nine Kenyan regions

    Running hands-on labs for university students across nine regions through 2026 and 2027, with a team of four running them in parallel.

  • Decode 2026, Nairobi

    Presented CONTAGION live: agentic worm propagation across a mesh of eight tool-using agents, and where the LLM judge guarding it fails.

  • Masinde Muliro University, Kakamega

    Taught the Break & Secure red team labs: build an AI app, attack it, secure it, then re-run the same attacks against the fix.

  • CyberDefender Snake, Decode 4.0

    Co-built the security workshop as a playable game. 42 forks, meaning people took it away and ran it themselves.

06 / contact

Get in touch

Happy to talk about AI security architecture, guardrail evaluation, or bringing the builder labs to a university or team.